
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
DocJet MCP server — render branded PDFs and PNG images from any MCP client. Tools: render_pdf, render_image, list_templates. Stdio transport, npx-runnable.
MCP server for DocJet — render branded PDF documents (invoices, reports, certificates) and PNG social images directly from any MCP client (Claude Desktop, Claude Code, Cursor, Windsurf, ...).
Send a template ID or raw HTML plus JSON data; get back a signed download URL. Runs locally over stdio via npx — nothing to host.
Add to your MCP client configuration:
{
"mcpServers": {
"docjet": {
"command": "npx",
"args": ["docjet-mcp"],
"env": {
"DOCJET_API_KEY": "binfra_your_key_here"
}
}
}
}
Get an API key at docjet.dev. To try it without signing up, use the public demo key (rate-limited to 3 req/min, 50 renders/month, shared by everyone):
binfra_9afb57dbb6478c441ad101129fca65847f5745403f9d718b3de6d934c9b63f88
| Tool | What it does |
|---|---|
render_pdf | Render a branded PDF. Input: template_id (or raw html) + data object. Returns a signed download URL. |
render_image | Render a PNG image (e.g. OG/social card). Input: template_id (or raw html) + data object. Returns a signed download URL. |
list_templates | List available templates: id, name, description, outputType. No API key needed. |
Example prompt once connected:
"List the DocJet templates, then render the invoice-ro template with client 'Demo SRL' and total 1000 as a PDF."
| Variable | Required | Description |
|---|---|---|
DOCJET_API_KEY | Yes | Your DocJet API key (binfra_ prefix). Sent as a Bearer token; never logged. |
DOCJET_BASE_URL | No | Override the API base URL (default https://api.docjet.dev). |
@modelcontextprotocol/sdk (v1).render_pdf → POST /v1/render?response=url, render_image → POST /v1/image?response=url, list_templates → GET /v1/templates.^[a-z0-9][a-z0-9-]{0,63}$ before any network call.QUOTA_EXCEEDED, RATE_LIMITED).docjet on npmMIT
FAQs
DocJet MCP server — render branded PDFs and PNG images from any MCP client. Tools: render_pdf, render_image, list_templates. Stdio transport, npx-runnable.
We found that docjet-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.